MarketplacePrivacyIndia - DPDP Rules
PrivacyRegulation

India - DPDP Rules

India - Digital Personal Data Protection (DPDP) Rules

The Digital Personal Data Protection Rules, 2025 operationalize India’s Digital Personal Data Protection Act, 2023 by establishing detailed requirements for the collection, processing, storage, and protection of digital personal data. The Rules define obligations for organizations handling personal data, including consent management, breach notifications, data retention, and protections for children and vulnerable individuals. They also establish governance mechanisms such as the Data Protection Board and provide a phased implementation timeline for compliance.

Overview

The Digital Personal Data Protection Rules, 2025 create the practical framework for implementing India’s data privacy regime under the DPDP Act, 2023. The Rules require organizations (“data fiduciaries”) to obtain clear and informed consent, provide transparent privacy notices, limit data use to specified purposes, implement security safeguards, and enable individuals to exercise rights over their personal data.

The Rules introduce requirements for reporting personal data breaches, managing consent withdrawal, retaining and deleting data appropriately, and protecting children’s data through verifiable parental or guardian consent. They also regulate cross-border transfers of personal data and establish operational procedures for the Data Protection Board of India to oversee compliance, investigate violations, and address grievances.

Implementation is phased over multiple years, allowing organizations time to adapt compliance programs, governance processes, and technical controls. Overall, the Rules aim to strengthen privacy protection, accountability, and responsible digital data use while balancing individual rights with legitimate data processing needs in India’s digital economy.

Related in Privacy

PrivacyLaw

Croatia - Personal Data Protection Act

The Act governs the implementation of the EU General Data Protection Regulation (GDPR) in Croatia. It outlines specific roles such as the responsibilities of the supervisory authority, the Croatian Data Protection Agency (AZOP), and sets additional national measures related to GDPR compliance.

Government of Croatia • Croatia

View details
PrivacyLaw

Maine Notice of Risk to Personal Data — Title 10, Chapter 210-B: Notice of Risk to Personal Data

Maine's Title 10, Chapter 210-B establishes regulations around personal data protection and security breach notifications. It includes provisions on prohibited use of personal data, mandatory breach notification, enforcement mechanisms, and rules for reporting identity theft.

State of Maine • Maine, USA

View details
PrivacyLaw

France Act no. 78-17 of 6 January 1978 — Act no. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties

This French law governs the protection of personal data and the rights of individuals in relation to data processing. It sets principles for the use of information technology to ensure it serves citizens without violating human rights, privacy, or individual liberties.

Government of France • France

View details
PrivacyLaw

Law No.59 — Vietnam - Law on Protection of Consumers' Rights

The Vietnam Law on Protection of Consumers' Rights is a consumer protection framework that establishes consumer rights, business obligations, consumer information protection requirements, and mechanisms for resolving disputes between consumers and traders.

Government of Vietnam • Vietnam • vLaw No.59/2010/QH12

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call